Europe Series

The CRA Reporting Clock Starts on 11 September 2026

The Cyber Resilience Act (CRA) comes into effect on 11 September 2026, mandating manufacturers to report exploited vulnerabilities and severe product-security incidents within specified timeframes. Initial obligations begin immediately, despite broader compliance deadlines in December 2027. Companies must establish effective reporting processes to ensure timely and accurate notifications regarding product security.

The EU Data Act Is a Cloud-Exit Law as Much as an IoT Law

The EU Data Act, effective from 12 September 2025, grants users rights to access and share data from connected products, aiming to enhance data portability and interoperability. It imposes new requirements on cloud service providers to facilitate easier switching and data extraction, fundamentally altering infrastructure and user access dynamics.

Healthcare Cybersecurity in Europe: From Guidance to Operational Readiness

The European Commission's action plan, launched in January 2025, aims to enhance cybersecurity in hospitals and healthcare providers, recognising its vital role in patient safety. The plan focuses on prevention, detection, response, recovery, and deterrence, providing guidance and resources tailored to the sector's unique needs, while integrating existing regulations like GDPR and NIS2.